Skip to content

Security: pin oauthlib>=4.0.0 (CVE-2026-49264, CVE-2026-49265) #2720

Description

@friedrichwilken

Two CVEs were published against oauthlib affecting all 3.x releases:

  • CVE-2026-49265 -- Timing attack vulnerability in PKCE code_verifier comparison (CWE-208)
  • CVE-2026-49264 -- Unsafe JSONP callback injection in RevocationEndpoint

Both are fixed in oauthlib 4.0.0.

The dependency chain here is:

kubernetes → requests-oauthlib → oauthlib>=3.0.0

requests-oauthlib declares oauthlib>=3.0.0, which allows resolvers to land on the vulnerable 3.x line. The upstream fix is requests/requests-oauthlib#577, but that project is slow-moving.

The same protective pattern was used before in #2016 -- adding a direct oauthlib pin to requirements.txt. A PR with the one-line fix is attached.

Once requests/requests-oauthlib#577 merges and a new requests-oauthlib release ships with the raised lower bound, this pin can be removed (same as #2434 cleaned up the previous one).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions